« Volver al listado

CVE-2019-11996

Estado: ModificadaCrítica (9.8)—

Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-11996",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "HPE Nimble Storage Hybrid Flash Arrays; Nimble Storage All Flash Arrays; Nimble Storage Secondary Flash Arrays",
          "versions": [
            {
              "status": "affected",
              "version": "5.1.2.0 and older, 5.0.7.0 and older, 4.5.4.0 and older, 3.9.1.0 and older"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-07T19:15:14.017",
  "references": [
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03964en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03964en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0."
    },
    {
      "lang": "es",
      "value": "Han sido identificadas posibles vulnerabilidades de seguridad con los sistemas HPE Nimble Storage en configuraciones de grupos de múltiples matrices. Las vulnerabilidades podrían ser explotadas por un atacante para obtener privilegios elevados en la matriz. Las siguientes versiones de NimbleOS, y todas las versiones posteriores, contienen una corrección de software para esta vulnerabilidad: 3.9.2.0, 4.5.5.0, 5.0.8.0 y 5.1.3.0."
    }
  ],
  "lastModified": "2026-06-17T02:13:59.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D075214A-20A3-4AA2-A35B-9B5F6DE26CF4",
              "versionEndIncluding": "3.9.1.0",
              "versionStartIncluding": "3.1.0.0"
            },
            {
              "criteria": "cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D18184C8-9D04-4F7C-A6AA-59BA85CB1577",
              "versionEndIncluding": "4.5.4.0",
              "versionStartIncluding": "4.1.0.0"
            },
            {
              "criteria": "cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B9295BF-5CF6-470F-AAAB-C24CB23C0406",
              "versionEndIncluding": "5.0.7.0",
              "versionStartIncluding": "5.0.1.0"
            },
            {
              "criteria": "cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66A86334-CC9B-4D33-AE33-E4B2F07CCC5D",
              "versionEndIncluding": "5.1.2.0",
              "versionStartIncluding": "5.1.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_af20_all_flash_array:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "80CF1BE0-0224-4190-BBC6-7D4373234E85"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_af20q_all_flash_dual_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D5E0887F-E894-4821-A171-96D758A8F8CE"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_af40_all_flash_dual_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "14AC79A7-DDF9-4212-AAEC-458FA7E5E06A"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_af60_all_flash_dual_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F7985641-BC1A-42B6-8B61-147848AB77AF"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_af80_all_flash_dual_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "508699FE-1F81-43EE-848F-203420217356"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_cs3000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DFD2E78D-2C8F-46BA-804C-10110687F148"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_cs5000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DB8C5FF4-BF19-4E0C-BDED-AEBE75E95D7C"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_cs7000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "009451E7-756D-47DD-954F-5041389E7C36"
            },
            {
              "criteria": "cpe:2.3:h:hpe:nimble_storage_secondary_flash_arrays:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DD1E0DC2-CBA3-4921-8458-705F6709E3D5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}